57,566 vulnerabilities published in 2026
Improper handling of filenames in certain HIKSEMI NAS products may lead to the exposure of sensitive system files.
Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-s
Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protecti
For WRC-X1500GS-B and WRC-X1500GSA-B, the initial passwords can be calculated easily from the system information.
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to
Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has
FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an au
An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are n
Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoi
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.3 and i
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker w
Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Versions 1.7.0 and
A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function Redi
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local infor
Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Ma
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerabi
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th
Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their ni
Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of Java
ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject
OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows at
Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the t
Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could st
The issue was addressed with improved authentication. This issue is fixed in iOS 26.4 and iPadOS 26.4, visionOS 26.4, wa
The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. An attacker with physical
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optiona
Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exis
BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET
Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler
A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize
An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Ver
OpenClaw before 2026.3.22 contains a service discovery vulnerability where TXT metadata from Bonjour and DNS-SD could in
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML inje
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-539
A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an una
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with
Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a store
In the Linux kernel, the following vulnerability has been resolved: ALSA: usx2y: us144mkii: fix NULL deref on missing i
OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failure
OpenClaw before 2026.4.2 contains an improper access control vulnerability in the iOS A2UI bridge that treats generic lo
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started